CVE-2016-15055
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
12/11/2025
Last modified:
12/11/2025
Description
JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
References to Advisories, Solutions, and Tools
- http://pro.jvc.com/prof/attributes/tech_desc.jsp?model_id=MDL102145&feature_id=02
- https://web.archive.org/web/20170713051843/http://www.black-rose.ml/2016/08/analyzing-security-cameras-products.html
- https://www.exploit-db.com/exploits/40282
- https://www.vulncheck.com/advisories/jvc-vnt-ip-camera-directory-traversal-via-check-cgi



